VDB
Sign up
—

RUSTSEC-2026-0113

`unpack_in` can chmod arbitrary directories by following symlinks

Details

In versions 0.6.0 and earlier of astral-tokio-tar, the unpack_in API could inadvertently modify the permissions of external (i.e. non-archive) directories outside of the archive. An attacker could use this to contrite a tar archive that maliciously changes directory permissions outside of its intended hierarchy. This flaw only affects directories; individual file permissions cannot be modified via it.

See GHSA-j4xf-2g29-59ph for the equivalent flaw in the tar crate.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/astral-tokio-tar
Introduced in: 0.0.0-0Fixed in: 0.6.1

Upgrade astral-tokio-tar to 0.6.1 or newer (ecosystem crates.io).

References